Live data from Hacker News

Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

techdirt.com

311–320 of 364 posts

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#311
post #2

> Apple ... will probably have little time to debug or test it overall, meaning that this feature it is being ordered to build will almost certainly put more users at risk. Eh? They are not being asked to install it to the public at large, just one phone. Of all reasons to object, this reason makes little sense.

It's much more than tha. If they do it "just this once", that means they can allow others to get to encrypted data, despite what they've been claiming all along. It's a very binary situation.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#312

Earlier quoted context omitted.

Why?

Because designing a law that makes sense when interpreted strictly formally is a friendly-AI-equivalent problem, i.e. it requires figuring out what values humans actually care about and then implementing it in a system that can outsmart anyone trying to game it. Failing that, people will get hurt by corner cases in such a law, or suffer abuse from people gaming the system.

There is a different point to be made here though. You can't predict everything ahead of time, but what do you do when somebody finds an edge case?

For the future the answer is obvious. You consider the edge case, decide what to do what it happens, publish the decision and follow it from now on.

The real question is, what do you do for the person who fell into the edge case before it was decided?

And the problem with the existing criminal justice system is that the judge decides how that edge case should be handled and then imposes it on the defendant's behavior ex post facto. Which the courts don't allow Congress to do but seem to have no problem doing themselves.

There is a fair argument to be made that we should let the first defendant who does it get away with it, but then publish the decision saying that it was wrong and imposing that on the next one.

It's kind of like the exclusionary rule: Somebody getting away with something that one time would be the punishment Congress gets for not considering more of the edge cases from the outset (or passing simpler laws that are easier to reason about).

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#313
post #249

For me, the most interesting question I would have is absent from the article. The court is basically ordering Apple to produce new firmware that doesn't block brute forcing. If Apple were to comply, who keeps this firmware after the fact? There's no mention of this at all, but if the firmware image stays with the FBI then the implications are much more profound with regard to privacy.

>The SIF will be coded by Apple with a unique identifier of the phone so that the SIF would only load and execute on the SUBJECT DEVICE. If I understand the cited order correctly the firmware is ordered to be constructed in a way that it runs only on the target phone.

I do wonder though that had Apple not predicted this exact scenario ahead of time (likely), how would they control this?

It's unlikely they can rely on hardware protections to provide this device locking, so is it the case that they would build the unique identifier into the image.

Optimistically some obfuscation could help but are the FBI/CIA/NSA really more than a few hops away from opening the binary image in a hex editor and changing it by hand?

If Apple firmware images for the iPhone are signed per-device then fine, but is that the case?

I don't know this but it seems unlikely to me that a custom device-signed build of iOS happens for every iDevice, and if that's not the case, I can't see how Apple can reliably restrict this with confidence.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#314
post #11

Earlier quoted context omitted.

That's true. In fact, if it's possible for Apple to accomplish what DOJ is demanding of it, the best outcome would be for DOJ to succeed, and do so publicly: * There is an authentic need to get at the data on that phone * There's no likelihood at all that other users will be impacted by the backdoor * We'll all be on the same page about how secure these phones are versus the USG. It's possible that they can prevail a…

> * There's no likelihood at all that other users will be impacted by the backdoor That could not be further from the truth . They are trying to set a precedent that endangers the future of consumer end-to-end encryption. They are trying to repurpose an 18th-century law (the All Writs law) to force Apple to help them break iPhone encryption. If this case creates precedent, what is to stop them from, say, forcing Sign…

You and Cardozo are hyperventilating.

The DOJ can make this demand because Apple phones of this vintage are already breakable, and the DOJ is merely asking Apple to exercise a capability it already has.

Apple knows this, better than most, and has for many years. They have done security design work with governments as an explicit adversary. The 5C was insecure. The 5S is not: it has an entire additional processor, running an incredibly secure OS, whose entire job is to make sure that the phone keeps promises like these even if the DOJ orders Apple to sign bogus updates.

Apple is so committed to this that they've extended the "ten tries and you're out" promise all the way through their server infrastructure, so that if you escrow data into iCloud it will be nuked if someone tries to brute force it. Not only that, but after rigging their HSM cluster to operate that way, they burned the update keys, so that an attempt to change that rule will break all of iCloud.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#315
post #228

Earlier quoted context omitted.

Brute forcing a password could take more time, with today's technology, than we have left on Earth depending on complexity and if there are known vulnerabilities. I'm not sure I would effectively consider this order an order to "unencrypt".

Passcodes are only 4 or 6 digits.

Maybe? Do we even know what type of passcode they used? If they turned off simple passcode then they could have entered anything they wanted at varying lengths.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#316

Earlier quoted context omitted.

Because designing a law that makes sense when interpreted strictly formally is a friendly-AI-equivalent problem, i.e. it requires figuring out what values humans actually care about and then implementing it in a system that can outsmart anyone trying to game it. Failing that, people will get hurt by corner cases in such a law, or suffer abuse from people gaming the system.

There is a different point to be made here though. You can't predict everything ahead of time, but what do you do when somebody finds an edge case? For the future the answer is obvious. You consider the edge case, decide what to do what it happens, publish the decision and follow it from now on. The real question is, what do you do for the person who fell into the edge case before it was decided? And the problem with…

It's just not possible.

It's like arguing that the developers of Windows or MacOS or Linux or whatever should just start over and do everything right this time. Or Intel and AMD should create a new CPU architecture and do it right this time. What you'll quickly find are a million reasons why things are done the way they are, and that this whole restarting project was a terrible idea.

Yeah it sounds great, but anyone who knows what that actually means realizes it's a retarded idea.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#317
post #286

Earlier quoted context omitted.

The fact that courts don't have ways to handle edge cases is a huge problem with our case law style legal system.

You ever get in a fight with someone? You ever get in a fight where it wasn't 100% clear who was right and who was wrong? You were both a little bit right and a little bit wrong? Welcome to the problems our legal system has to deal with. The world isn't a mathematical equation. It's fuzzy. So is our legal system.

> You ever get in a fight where it wasn't 100% clear who was right and who was wrong? You were both a little bit right and a little bit wrong?

I'm not really sure what point you're trying to make. Yes, the world is not black and white, but neither is math.

If you have e.g. a car crash where one person was speeding and the other failed to yield the right of way, they're both at fault. Maybe one is more at fault than the other and therefore has to pay a higher percentage of the damages, but how is that not still an algorithm?

The hard part is designing the right algorithm ahead of time. But throwing up your hands and saying that problem is hard and therefore we should give up on having laws and just let judges decide everything on a case by case basis isn't democracy and isn't the rule of law. It's the rule of whatever the judge says it is today.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#318
post #13

Earlier quoted context omitted.

After five failed fingerprint attempts, your password is required to unlock the phone. That seems pretty safe to me. If you're ever ordered to unlock the phone, just touch an unregistered finger to it. Fingerprint sensors aren't foolproof. It'd be hard to prove you deliberately sabotaged the effort. Though, one feature I'd like would be to register a distress fingerprint. Then I could touch say... my left index finge…

They would fingerprint the reader, and you, to get a rough idea of which finger is a likely candidate. Even an extremely partial print should be enough to narrow it down to 4 or 5. The reality is that all right-handed people hold phones in their left and so use fingers on their right hand. Lefties do the reverse. So it is already down to five candidates ... which might have something to do with why apple picked that…

...where on earth did you get that idea from? I'm right-handed and both hold and unlock my phone with the fingers on my right hand.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#319

Earlier quoted context omitted.

There is a different point to be made here though. You can't predict everything ahead of time, but what do you do when somebody finds an edge case? For the future the answer is obvious. You consider the edge case, decide what to do what it happens, publish the decision and follow it from now on. The real question is, what do you do for the person who fell into the edge case before it was decided? And the problem with…

It's just not possible. It's like arguing that the developers of Windows or MacOS or Linux or whatever should just start over and do everything right this time. Or Intel and AMD should create a new CPU architecture and do it right this time. What you'll quickly find are a million reasons why things are done the way they are, and that this whole restarting project was a terrible idea. Yeah it sounds great, but anyone…

It's not possible to make a perfect system. It's completely possible to let the first person to find an imperfection take advantage of it but then immediately fix it.

Which would create an incentive for finding imperfections and therefore fix more of them faster.

Re: Apple ordered to bypass auto-erase on San Bernadino shooter's iPhone

#320
post #286

Earlier quoted context omitted.

You ever get in a fight with someone? You ever get in a fight where it wasn't 100% clear who was right and who was wrong? You were both a little bit right and a little bit wrong? Welcome to the problems our legal system has to deal with. The world isn't a mathematical equation. It's fuzzy. So is our legal system.

> You ever get in a fight where it wasn't 100% clear who was right and who was wrong? You were both a little bit right and a little bit wrong? I'm not really sure what point you're trying to make. Yes, the world is not black and white, but neither is math. If you have e.g. a car crash where one person was speeding and the other failed to yield the right of way, they're both at fault. Maybe one is more at fault than t…

It's impossible to design an appropriate algorithm ahead of time capable of accepting all of the possible inputs that might occur.

Which isn't to say that we shouldn't do our best. We shouldn't just throw up our hands. But I think it's important to admit that judges will always be necessary to handle inevitable ambiguities.

Post reply on HN